North Korea’s Contagious Interview Campaign Spreads Across 5 Ecosystems, Delivering Staged RAT Payloads
Blog post from Socket
Since 2024, over 1,700 malicious packages linked to North Korea's Contagious Interview operation have been tracked, with recent developments revealing a new cluster of threat actors operating under GitHub aliases like golangorg. They have published malware across multiple open-source ecosystems, impersonating legitimate developer tools while functioning as malware loaders. These malicious packages, spread across npm, PyPI, Go Modules, Rust’s crates.io, and PHP's Packagist, include functionalities for remote access, keylogging, and data theft, including browser and cryptocurrency wallet data. The threat actors hide their malicious code behind seemingly legitimate functions within these packages, making them difficult to detect. The operation's infrastructure and package construction are consistent with Contagious Interview's previous tactics, utilizing a coordinated cross-ecosystem supply chain strategy. Efforts to remove these packages from affected registries are ongoing, and the campaign underscores the importance of scrutinizing utility packages that interact with remote infrastructure.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.